CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3667 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-4613 | LG LED Assistant 路径遍历漏洞 — LG-LED Assistant | 9.8 | Critical | 2023-09-04 |
| CVE-2023-41747 | Acronis Cloud Manager 输入验证错误漏洞 — Acronis Cloud Manager | 7.5 | - | 2023-08-31 |
| CVE-2023-41044 | Graylog 路径遍历漏洞 — graylog2-server | 3.3 | Low | 2023-08-31 |
| CVE-2023-31167 | Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder 路径遍历漏洞 — SEL-5036 acSELerator Bay Screen Builder Software | 5.0 | Medium | 2023-08-31 |
| CVE-2023-41040 | GitPython 路径遍历漏洞 — GitPython | 4.0 | Medium | 2023-08-30 |
| CVE-2023-40587 | Pyramid 路径遍历漏洞 — pyramid | 4.3 | Medium | 2023-08-25 |
| CVE-2023-3406 | M-Files 路径遍历漏洞 — M-Files Web | 7.7 | High | 2023-08-25 |
| CVE-2023-32756 | e-Excellence U-Office Force 路径遍历漏洞 — U-Office Force | 7.5 | High | 2023-08-25 |
| CVE-2023-25914 | Danfoss AK-SM800A 路径遍历漏洞 — AK-SM800A | 8.8 | High | 2023-08-21 |
| CVE-2023-2971 | Typora 路径遍历漏洞 — Typora | 6.3 | Medium | 2023-08-19 |
| CVE-2023-2316 | Typora 路径遍历漏洞 — Typora | 7.4 | High | 2023-08-19 |
| CVE-2023-2110 | Obsidian 路径遍历漏洞 — Obsidian | 8.2 | High | 2023-08-19 |
| CVE-2023-3698 | ASUSTOR Data Master 路径遍历漏洞 — ADM | 8.5 | High | 2023-08-17 |
| CVE-2023-3697 | ASUSTOR Data Master 路径遍历漏洞 — ADM | 8.5 | High | 2023-08-17 |
| CVE-2023-34217 | MOXA TN-4900 路径遍历漏洞 — TN-5900 Series | 8.1 | High | 2023-08-17 |
| CVE-2023-34216 | MOXA TN-4900 路径遍历漏洞 — TN-5900 Series | 8.1 | High | 2023-08-17 |
| CVE-2023-20229 | Cisco Duo 路径遍历漏洞 — Cisco Duo Device Health Application | 7.1 | High | 2023-08-16 |
| CVE-2023-40028 | Ghost Foundation Ghost 后置链接漏洞 — Ghost | 4.9 | Medium | 2023-08-15 |
| CVE-2023-39402 | Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS | 9.8 | - | 2023-08-13 |
| CVE-2023-39401 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | 9.8 | - | 2023-08-13 |
| CVE-2023-39400 | Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS | 9.8 | - | 2023-08-13 |
| CVE-2023-39964 | 1Panel 路径遍历漏洞 — 1Panel | 7.5 | High | 2023-08-10 |
| CVE-2023-39957 | Nextcloud Talk 路径遍历漏洞 — security-advisories | 3.3 | - | 2023-08-10 |
| CVE-2023-36534 | Zoom Client 路径遍历漏洞 — Zoom Desktop Client for Windows | 9.3 | Critical | 2023-08-08 |
| CVE-2023-38176 | Microsoft Azure Arc 安全漏洞 — Azure Arc-Enabled Servers | 7.0 | High | 2023-08-08 |
| CVE-2023-39528 | PrestaShop 路径遍历漏洞 — PrestaShop | 6.8 | Medium | 2023-08-07 |
| CVE-2023-39525 | PrestaShop 路径遍历漏洞 — PrestaShop | 6.5 | Medium | 2023-08-07 |
| CVE-2020-26065 | Cisco SD-WAN vManage Software 路径遍历漏洞 — Cisco SD-WAN vManage | 6.5 | - | 2023-08-04 |
| CVE-2023-38702 | Knowage 路径遍历漏洞 — Knowage-Server | 10.0 | Critical | 2023-08-04 |
| CVE-2023-38695 | cypress-image-snapshot 路径遍历漏洞 — cypress-image-snapshot | 6.5 | Medium | 2023-08-04 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3667 条 CVE 漏洞。